'use strict';

var PASSWORD = 'dontaskme';

exports.portal = function* () {
    yield this.render('login');
};

exports.login = function* () {
    if (this.request.body.password === PASSWORD) {
        this.session.logined = true;
        this.redirect('/');
    } else {
        delete this.session.logined;
        this.status = 500;
        this.body = 'login failed';
    }
};
